Bugzilla – Bug 1193372
VUL-0: CVE-2021-28237: libredwg: heap-buffer overflow via decode_preR13.
Last modified: 2024-06-13 17:02:05 UTC
CVE-2021-28237 LibreDWG v0.12.3 was discovered to contain a heap-buffer overflow via decode_preR13. Upstream fix commit: https://github.com/LibreDWG/libredwg/commit/ea0b9522f63d049ded2c3cff8d9a8c360119951c References: http://web.nvd.nist.gov/view/vuln/detail?vulnId=CVE-2021-28237 http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2021-28237 https://github.com/LibreDWG/libredwg/issues/325 http://www.cvedetails.com/cve/CVE-2021-28237/
977606 977605
This is an autogenerated message for OBS integration: This bug (1193372) was mentioned in https://build.opensuse.org/request/show/977604 Factory / libredwg https://build.opensuse.org/request/show/977605 Backports:SLE-15-SP3 / libredwg https://build.opensuse.org/request/show/977606 Backports:SLE-15-SP4 / libredwg
openSUSE-SU-2022:0149-1: An update that fixes two vulnerabilities is now available. Category: security (moderate) Bug References: 1193372,1194767 CVE References: CVE-2021-28237,CVE-2022-21658 JIRA References: Sources used: openSUSE Leap 15.3 (src): rust1.56-1.56.1-150300.7.6.1 openSUSE Backports SLE-15-SP3 (src): libredwg-0.12.5-bp153.2.3.1
openSUSE-SU-2022:0155-1: An update that fixes one vulnerability is now available. Category: security (moderate) Bug References: 1193372 CVE References: CVE-2021-28237 JIRA References: Sources used: openSUSE Backports SLE-15-SP4 (src): libredwg-0.12.5-bp154.2.3.1